Freebsd

Freebsd

575 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 26.08.2026 05:39:42
  • Zuletzt bearbeitet 24.09.2026 13:17:24

The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after creating the object, before any memory is allocated for the object. The handler checked whether a page...

  • EPSS 0.09%
  • Veröffentlicht 26.08.2026 05:33:30
  • Zuletzt bearbeitet 24.09.2026 13:25:33

The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being dest...

  • EPSS 0.22%
  • Veröffentlicht 26.08.2026 05:28:17
  • Zuletzt bearbeitet 10.09.2026 15:36:14

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitr...

  • EPSS 0.6%
  • Veröffentlicht 26.08.2026 05:28:09
  • Zuletzt bearbeitet 10.09.2026 15:39:04

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026...

  • EPSS 0.6%
  • Veröffentlicht 26.08.2026 05:28:00
  • Zuletzt bearbeitet 10.09.2026 15:39:29

mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially execute arbitr...

  • EPSS 0.15%
  • Veröffentlicht 26.08.2026 04:46:17
  • Zuletzt bearbeitet 24.09.2026 13:34:50

In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored ...

  • EPSS 0.13%
  • Veröffentlicht 26.08.2026 04:38:19
  • Zuletzt bearbeitet 24.09.2026 13:55:22

The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync group list lock and sleeps. Upon reawakening, it is possible that the sync group structure is freed, ...

  • EPSS 0.13%
  • Veröffentlicht 26.08.2026 04:35:10
  • Zuletzt bearbeitet 24.09.2026 14:01:08

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. ...

  • EPSS 0.12%
  • Veröffentlicht 26.08.2026 04:30:06
  • Zuletzt bearbeitet 24.09.2026 14:06:22

When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user who has attache...

  • EPSS 0.14%
  • Veröffentlicht 19.08.2026 07:52:13
  • Zuletzt bearbeitet 31.08.2026 15:04:36

The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program headers, then iterated over the map a second time to populate them. A process sharing the address space via rfork(2) can mutate th...